For the person who has to say yes

Security & data posture.

This is the page to hand to whoever has to sign off on putting a box on the network.

Can Spall write to my PLCs?
No. Spall is read-only by contract: it reads tags on a schedule and never issues a write. It recommends. Your people act. There is no code path in the product that writes back to a controller.
Does anything connect inbound to the plant?
No. The edge gateway makes outbound-only connections: machine data goes out over MQTT to the cloud. The gateway runs no remote-login service of any kind, not by default and not on request: there is nothing to enable, no standing tunnel, no shell. If support ever needs a hands-on look, it is done in person: a visit to the on-site console, or a straight device swap. Nothing works over the internet. The one thing the gateway serves on the plant side is its own setup console, a local page on the gateway used to claim the device and set its network. It is reachable only from the network segment the gateway sits on, and it can be switched off in the gateway configuration.
Is our data locked into Spall?
No. Data leaves through live Excel/OData feeds, direct SQL views, and a REST API: the same data your dashboards see, queryable on your terms. If you leave, you take your history with you.
Can one customer see another customer’s data?
No. Every customer is isolated at the API layer: every query is scoped to the account it belongs to, not left to client-side filtering. A super-admin role exists for box-wide operations but is separate from customer accounts.
Can we require two factor authentication for admin logins?
Yes. Admin accounts can enroll standard TOTP two factor authentication, with backup recovery codes, from their own account settings, and an admin can turn on a tenant wide setting that requires it for every admin account on the tenant.
How are secrets handled?
Secrets live in an env file (access-controlled, never committed or logged) by default, with an opt-in hardened layer using Docker secrets (file-based, mounted read-only) for anything that needs a higher bar. Diagnostics exports are redacted before they leave the box: no secret value, and no field whose name looks sensitive, is ever present in an export.
What actually runs on the box?
A local edge agent and a local data buffer. If the internet connection drops, the agent keeps reading tags and buffering on-site, then backfills the cloud once connectivity returns. A plant floor outage doesn't lose history.
What happens when the data is thin or missing?
Missing data shows as a dash. The AI answers only when a signal has enough history behind it, and says so otherwise.
How do we report a security vulnerability?
Email hello@spall.cc with what you found. Every report is acknowledged within five business days, best effort, no bounty program. The machine readable policy lives at /.well-known/security.txt.

01

Read-only, always

02

Outbound-only networking

03

Your data, portable anytime

04

Secrets redacted on export

Bring your questionnaire. We'll fill it out straight.